39-51
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 39 Configuring the Switch Access Using AAA
Configuring Authorization on the Switch
Authorization Example
Figure 39-4
shows a simple network topology using .
When Workstation A initiates a command on the switch, the switch registers a request with the
daemon. The daemon determines if the user is authorized to use the feature and
sends a response either executing the command or denying access.
Figure 39-4
Example Network Topology
In this example, authorization is enabled for enable mode access and for the configuration
commands to be entered on the switch over the Telnet and console connections:
Console> (enable)
set authorization enable enable deny both
Successfully enabled enable authorization.
Console> (enable)
set authorization commands enable config deny both
Successfully enabled commands authorization.
Console> (enable)
show authorization
Telnet:
-------
Primary Fallback
------- --------
exec:
deny
enable:
deny
commands:
config:
deny
all: - -
Console:
--------
Primary Fallback
------- --------
exec:
deny
enable:
deny
commands:
config:
deny
all: - -
Console> (enable)
Workstation A
server
172.20.52.10
Switch
Terminal
Console port
connection
18927