Enables AAA support for commands entered at the console.
Syntax
enable aaa consoleno enable aaa console
Command Default
Command authorization and command accounting for console commands are not enabled.
Modes
Global configuration mode
Usage Guidelines
The ICX device supports command authorization and command accounting for CLI commands
entered at the console.
AAA support for commands entered at the console includes the following:
The login prompt that uses AAA authentication, using authentication method lists
EXEC authorization
EXEC accounting
Command authorization
Command accounting
System accounting
The
no form of the command disables the support for AAA commands entered at the console.
Note: If you have previously configured the device to perform command authorization using
a RADIUS server, entering the
enable aaa console command may prevent the execution of any subsequent commands entered on the console.
This happens because RADIUS command authorization requires a list of allowable commands
from the RADIUS server. This list is obtained during RADIUS authentication. For console
sessions, RADIUS authentication is performed only if you have configured
aaa authentication enable and specified RADIUS as the authentication method (for example, with the
aaa authentication enable default radius command). If RADIUS authentication is never performed, the list of allowable commands
is never obtained from the RADIUS server. Consequently, there would be no allowable
commands on the console.
If this command is configured, the DHCP client does not request the configuration
files as part of the DHCP client auto-provisioning process. Refer to the
RUCKUS FastIron DHCP Configuration Guide for more information.
Examples
The following example shows how to configure command authorization and command accounting
for console commands.