Radius Authorization; Configuring Authorization; Authorization Default Configuration; Tacacs+ Authorization Configuration Guidelines - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Configuring Authorization

The following TACACS+ authorization process occurs for every command that you enter:

RADIUS Authorization

RADIUS has limited authorization. The Service-Type attribute in the authentication protocol provides
authorization information. This attribute is part of the user profile.
When you log in using RADIUS authentication and you do not have Administrative/Shell (6)
Service-Type access, the NAS authenticates you and logs you in to EXEC mode if authentication
succeeds. If you have Administrative/Shell (6) Service-Type access, the NAS authenticates you and logs
you in to privileged mode if authentication succeeds.
Configuring Authorization
The following sections describe how to configure authorization.

Authorization Default Configuration

Table 30-3
Table 30-3 Default Authorization Configuration
Feature
TACACS+ login authorization (console and Telnet)
TACACS+ EXEC authorization (console and Telnet)
TACACS+ enable authorization (console and Telnet)
TACACS+ commands authorization (console and Telnet)

TACACS+ Authorization Configuration Guidelines

This section describes the guidelines for configuring authorization on the switch:
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
30-42
If you have disabled the command authorization feature, the TACACS+ server allows you to execute
any command on the switch.
If you have enabled authorization for configuration commands only, the switch verifies that the
argument string matches one of the commands listed above. If there is no match, the switch
completes the command. If there is a match, the switch forwards the command to the NAS for
authorization.
If you have enabled authorization for all commands, the switch forwards the command to the NAS
for authorization.
shows the default authorization configuration.
TACACS+ authorization is disabled by default.
Authorization configuration applies to console connections, Telnet connections, or both types of
connections.
You must specify the mode, primary option, fallback option, and connection type when enabling
authorization.
Chapter 30
Configuring Switch Access Using AAA
Default
Disabled
Disabled
Disabled
Disabled
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents