Aaa Authorization Commands - Allied Telesis x510-28GTX Command Reference Manual

Stackable gigabit edge switches x510 series
Table of Contents

Advertisement

AAA C
OMMANDS

AAA AUTHORIZATION COMMANDS

aaa authorization commands
Overview
This command configures a method list for commands authorization that can be
applied to console or VTY lines. When command authorization is enabled for a
privilege level, only authorized users can executed commands in that privilege
level.
Use the no variant of this command to remove a named method list or disable the
default method list for a privilege level.
aaa authorization commands <privilege-level>
Syntax
{default|<list-name>} group tacac+ [none]
no aaa authorization commands <privilege-level>
{default|<list-name>}
Mode
Global Configuration
Usage
TACACS+ command authorization provides centralized control of the commands
available to a user of an AlliedWare Plus device. Once enabled:
C613-50170-01 Rev B
Parameter
<privilege-level>
group
tacac+
default
<list-name>
none
The command string and username are encrypted and sent to the first
available configured TACACS+ server (the first server configured) for
authorization.
Command Reference for x510 Series
AlliedWare Plus™ Operating System - Version 5.4.7-1.x
Description
The privilege level of the set of commands the method list
will be applied to.
AlliedWare Plus defines three sets of commands, that are
indexed by a level value:
Level = 1: All commands that can be accessed by a user
with privilege level between 1 and 6 inclusive
Level = 7: All commands that can be accessed by a user
with privilege level between 7 and 14 inclusive
Level = 15: All commands that can be accessed by a user
with privilege level 15
Specify the server group where authorization messages are
sent. Only the tacacs+ group is available for this
command.
Use all TACACS+ servers configured by the
host
command.
Configure the default authorization commands method list.
Configure a named authorization commands method list
If specified, this provides a local fallback to command
authorization so that if authorization servers become
unavailable then the device will accept all commands
normally allowed for the privilege level of the user.
tacacs-server
1853

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents