enable aaa console

Enables AAA support for commands entered at the console.
Syntax
enable aaa console
no enable aaa console
Command Default

Command authorization and command accounting for console commands are not enabled.

Modes

Global configuration mode

Usage Guidelines

The ICX device supports command authorization and command accounting for CLI commands entered at the console.

AAA support for commands entered at the console includes the following:

  • The login prompt that uses AAA authentication, using authentication method lists
  • EXEC authorization
  • EXEC accounting
  • Command authorization
  • Command accounting
  • System accounting

The no form of the command disables the support for AAA commands entered at the console.

Note: If you have previously configured the device to perform command authorization using a RADIUS server, entering the enable aaa console command may prevent the execution of any subsequent commands entered on the console. This happens because RADIUS command authorization requires a list of allowable commands from the RADIUS server. This list is obtained during RADIUS authentication. For console sessions, RADIUS authentication is performed only if you have configured aaa authentication enable and specified RADIUS as the authentication method (for example, with the aaa authentication enable default radius command). If RADIUS authentication is never performed, the list of allowable commands is never obtained from the RADIUS server. Consequently, there would be no allowable commands on the console.

If this command is configured, the DHCP client does not request the configuration files as part of the DHCP client auto-provisioning process. Refer to the RUCKUS FastIron DHCP Configuration Guide for more information.

Examples

The following example shows how to configure command authorization and command accounting for console commands.

device(config)# enable aaa console