57
To do…
Use the command…
Remarks
Specify the scheme
authentication mode
authentication-mode
scheme
Required
Whether local, RADIUS, or
HWTACACS authentication is
adopted depends on the configured
AAA scheme.
By default, the authentication mode
is none for modem users
Enable command
authorization
command authorization
Optional
•
By default, command
authorization is not enabled.
•
By default, command level for a
login user depends on the user
privilege level. The user is
authorized the command with the
default level not higher than the
user privilege level. With the
command authorization
configured, the command level
for a login user is determined by
both the user privilege level and
AAA authorization. If a user
executes a command of the
corresponding command level,
the authorization server checks
whether the command is
authorized. If yes, the command
can be executed.
•
Before enabling command
authorization, configure the AAA
authorization server. After you
enable command authorization,
only commands authorized by
the AAA authorization server can
be executed.