Configuring Exec Authorization
When TACACS+ exec authorization is performed, the RUCKUS device consults a TACACS+ server to determine the privilege level of the authenticated user. To configure TACACS+ exec authorization on the RUCKUS device, enter the following command.
device(config)# aaa authorization exec default tacacs+
If you specify none or omit the aaa authorization exec command from the device configuration, no exec authorization is performed.
aaa authorization exec default
tacacs+ command to work, either the aaa authentication enable default
tacacs+ command or the aaa authentication login
privilege-mode command must also exist in the configuration.Configuring an Attribute-Value Pair on the TACACS+ Server
During TACACS+ exec authorization, the RUCKUS device expects the TACACS+ server to send a response containing an A-V (Attribute-Value) pair that specifies the privilege level of the user. When the RUCKUS device receives the response, it extracts an A-V pair configured for the Exec service and uses it to determine the user privilege level.
To set a user privilege level, you can configure the "foundry-privlvl" A-V pair for the Exec service on the TACACS+ server. Consider the following TACACS+ server configuration.
user=bob {
default service = permit
member admin
#Global password
global = cleartext "cat"
service = exec {
foundry-privlvl = 0
}
}
In the previous example, the A-V pair
foundry-privlvl = 0 grants the user full read-write access. The value in the foundry-privlvl A-V pair
is an integer that indicates the privilege level of the user. Possible values are
0 for super-user level, 4 for port-config level, or 5 for read-only level. If a value
other than 0, 4, or 5 is specified in the foundry-privlvl A-V pair, the default privilege
level of 5 (read-only) is used. The foundry-privlvl A-V pair can also be embedded
in the group configuration for the user. Refer to TACACS+ documentation for the configuration
syntax relevant to your server.
If the foundry-privlvl A-V pair is not present, the RUCKUS device extracts the last A-V pair configured for the Exec service that has a numeric value and uses this A-V pair to determine the user privilege level.
Consider the following TACACS+ server configuration.
user=bob {
default service = permit
member admin
#Global password
global = cleartext "cat"
service = exec {
privlvl = 15
}
}
In the example, the attribute name in the A-V pair is not significant; the RUCKUS device uses the last one that has a numeric value. However, the RUCKUS device interprets the value for a non-"foundry-privlvl" A-V pair differently than it does for a "foundry-privlvl" A-V pair. The following table lists how the RUCKUS device associates a value from a non-"foundry-privlvl" A-V pair with a RUCKUS privilege level.
RUCKUS Equivalents for Non-"foundry-privlvl" A-V Pair Values
Value for Non-"foundry-privlvl" A-V Pair |
|
|---|---|
15 |
0 (super-user) |
From 14 - 1 |
4 (port-config) |
Any other number or 0 |
5 (read-only) |
In the previous example, the A-V pair configured for the Exec service is
privlvl = 15. The
RUCKUS device uses the value in this A-V pair to set the user privilege level to 0 (super-user),
granting the user full read-write access.
In a configuration that has both a "foundry-privlvl" A-V pair and a non-"foundry-privlvl" A-V pair for the Exec service, the non-"foundry-privlvl" A-V pair is ignored.
Consider the following TACACS+ server configuration.
user=bob {
default service = permit
member admin
#Global password
global = cleartext "cat"
service = exec {
foundry-privlvl = 4
privlvl = 15
}
}
In the previous example, the user would be granted a privilege level of 4 (port-config
level). The
privlvl = 15 A-V pair is ignored by the
RUCKUS device.
If the TACACS+ server has no A-V pair configured for the Exec service, the default privilege level of 5 (read-only) is used.