Configuring Command Authorization
When TACACS+ command authorization is enabled, the RUCKUS device consults a TACACS+ server to obtain authorization for commands entered by the user.
You enable TACACS+ command authorization by specifying a privilege level for which commands require authorization. For example, to configure the RUCKUS device to perform authorization for the commands available at the Super User privilege level (that is, all commands on the device), enter the following command.
device(config)# aaa authorization commands 0 default tacacs+
The privilege-level parameter can be one of the following:
- 0: Authorization is performed for commands available at the Super User level (all commands).
- 4: Authorization is performed for commands available at the Port Configuration level (port-config and read-only commands).
- 5: Authorization is performed for commands available at the Read Only level (read-only commands).
TACACS+ command authorization is not performed for the following commands:
- At all levels: exit, logout, end, and quit
- At the Privileged EXEC level: enable or enable text, where text is the password configured for the Super User privilege level
If configured, command accounting is performed for these commands.
AAA Support for Console Commands
AAA support for commands entered at the console includes the following: