124
SIGNAMAX LLC • www.signamax.eu
method
Authorization method
if-authenticated: If a user passes the identity authentication, he is
authorized to access the request function.
Local: Use the local user database to authorize
None: Do not execute the authorization
Radius: Use RADIUS server to request the authorization information.
Tacacs: Use TACACS server to request the authorization information.
WORD: Use TACACS or RADIUS server to authenticate. WORD is the
name of the server group.
【
Default status
】
By default, the access authority is not restricted (being
equivalent to the keyword none).
【
Command mode
】
Global configuration mode
Note
When the EXEC authorization method list is configured and you execute
EXEC, NAS can implement the authorization to determine whether you
have the authority to execute the EXEC shell program; if NAS fails to
authorize, you can’t execute EXEC.
aaa authorization config-commands
This command is used to restrict the authority of the user to operate the
shell commands. The no form of the command is used to not restrict the
access authority.
aaa authorization config-commands
no aaa authorization config-commands
aaa authorization console
This command is used to restrict the authority of the user to enter the
system from the console port. The no form of the command is used to
not restrict the console port.
aaa authorization console
no aaa authorization console
aaa authorization commands
cmd-lvl
{default
|
list-name
}
method1
[
method2…
]
no aaa authorization
commands
cmd-lvl
{
default
|
list-name
}
Syntax
Description
config-commands
To configure AAA to permit command authorization
cmd-lvl
The command level to be authorized and the value range is 0-15.
default
To define the default method list
list-name
The name of the method list
method
Authorization method
if-authenticated: If a user passes the identity authentication, he is
authorized to access the request function.
Local: Use the local user database to authorize
None: Do not execute the authorization
Radius: Use RADIUS server to request the authorization information.
Tacacs: Use TACACS server to request the authorization information.
WORD: Use TACACS or RADIUS server to authenticate. WORD is the
name of the server group.
Summary of Contents for 065-7434
Page 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Page 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Page 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Page 368: ......
Page 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...