aaa authorization commands
aaa authorization
commands
privilege-level
default
radius
[
tacacs+
]
[
none
]no aaa authorization
commands
privilege-level
default
radius
[
tacacs+
]
[
none ]aaa authorization
commands
privilege-level
default
tacacs+
[
radius
]
[
none
]no aaa authorization
commands
privilege-level
default
tacacs+
[
radius
]
[
none
]aaa authorization
commands
privilege-level
default
noneno aaa authorization
commands
privilege-level
default
noneAAA authorization is not enabled.
Global configuration mode
You can configure RADIUS, TACACS+, and None as authorization methods. If the configured primary authorization fails due to an error, the device tries the backup authorization methods in the order they are configured.
When TACACS+ command authorization is enabled, the ICX device consults a TACACS+ server to get authorization for commands entered by the user.
When RADIUS command authorization is enabled, the ICX device consults the list of commands supplied by the RADIUS server during authentication to determine whether a user can issue a command that was entered.
TACACS+ command authorization is not performed for the following commands:
- At all levels:
exit,logout,end, andquit. - At the Privileged EXEC level:
enableorenabletext, where text is the password configured for the Super User privilege level.
Because RADIUS command authorization relies on the command list supplied by the RADIUS server during authentication, you cannot perform RADIUS authorization without RADIUS authentication.