Configuration Guide
AAA Configuration
Command
Function
aaa authorization exec
network
{
default
|
list-name} method1
[method2|…
]
Define the AAA Exec authorization method.
aaa authorization network
network
{
default
|
list-name} method1
[method2|…
]
Define the AAA Command authorization
method.
Configuring AAA Exec Authorization
The Exec authorization grants the privilege level of command execution for the user terminal
loggs in the network access server (NAS). You can use the
show privilege
command to
display the specific level after the user loggs in the NAS CLI successfully (by telnet, for
example).
No matter which Exec authorization method you decide to use, you just need to execute the
aaa authorization exec
command to define one or more authorization method list and apply it
to the specific line that need the Exec authorization.
To configure the AAA Exec authorization, run the following commands in the global
configuration mode:
Command
Function
configure terminal
Enter the global configuration mode.
aaa new-model
Turn on the AAA switch.
aaa authorization exec
network
{
default
|
list-name} method1
[method2|…
]
Define the AAA Exec authorization method. If
you need to define multiple methods, execute
this command repeatedly.
line vty
line-num
Enter the line to which the AAA Exec
authorization method is applied.
authorization exec
{
default
|
list-name
}
Apply the method to the line.
The keyword "list-name" is used to name the created authorization method list, which can be
any string. The keyword "method" means the actual algorithm for authorization. Only when the
current method returns ERROR (no reply), the next authorization method will be attempted. If
the current method returns FAIL, no authorization method will be used any more. To make the
authorization return successfully, even if no specified methods reply, it is possible to specific
"none" as the last authorization method.
In the example below, it is possible to pass the Exec authorication even if the Radius server
returns TIMEOUT
:
aaa authorization exec default group radius none
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...