
30-43
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Chapter 30 Configuring Switch Access Using AAA
Configuring Authorization
•
Configure RADIUS and servers before enabling authorization. See the
“Specifying
Servers” section on page 30-17
or the
“Specifying RADIUS Servers” section on
page 30-23
for more information on server setup.
•
Configure RADIUS and keys to encrypt protocol packets before enabling authorization.
See the
“Specifying the Key” section on page 30-19
or the
“Specifying the RADIUS
Key” section on page 30-25
for more information on the key setup.
Configuring Authorization
The next two sections describe how to configure authorization on the switch.
Enabling Authorization
To enable authorization on the switch, perform this task in privileged mode:
This example shows how to enable EXEC mode authorization for both console and Telnet
connections. Authorization is configured with the option. The fallback option is deny.
Console> (enable) set authorization exec enable deny both
Successfully enabled enable authorization.
Console>
This example shows how to enable enable mode authorization for console and Telnet
connections. Authorization is configured with the option. The fallback option is deny.
Console> (enable) set authorization enable enable deny both
Successfully enabled enable authorization.
Console>
Task
Command
Step 1
Enable authorization for normal login mode.
Enter the console or telnet keywords if you want
to enable the authorization only for the console
port or for the Telnet connection attempts. Enter
the both keyword to enable authorization for both
console port and Telnet connection attempts.
set authorization exec enable {option}
{fallbackoption} [console | telnet | both]
Step 2
Enable authorization for enable mode. Enter the
console or telnet keywords if you want to enable
the authorization only for the console port or for
the Telnet connection attempts. Enter the both
keyword to enable authorization for both console
port and Telnet connection attempts.
set authorization enable enable {option}
{fallbackoption} [console | telnet | both]
Step 3
Enable authorization of configuration commands.
Enter the console or telnet keywords if you want
to enable the authorization only for the console
port or for the Telnet connection attempts. Enter
the both keyword to enable authorization for both
console port and Telnet connection attempts.
set authorization commands enable {config |
all} [option} {fallbackoption} [console | telnet |
both]
Step 4
Verify the authorization configuration. show authorization