Configuring Tacacs+ Authorization For Privileged Exec Access; And Network Services - Allen-Bradley Stratix 5100 User Manual

Wireless access point/workgroup bridge
Hide thumbs Also See for Stratix 5100:
Table of Contents

Advertisement

7. Verify your entries.
show running-config
8. (Optional) Save your entries in the configuration file.
copy running-config startup-config
• To disable AAA, use the
command.
• To disable AAA authentication, use the
login {default |
configuration command.
• To either disable TACACS+ authentication for logins or to return to the
default value, use the
name} line configuration command.
Configuring TACACS+ Authorization for Privileged EXEC Access and
Network Services
AAA authorization limits the services available to a user. When AAA
authorization is enabled, the wireless device uses information retrieved from the
user profile, that is either in the local user database or on the security server, to
configure the user session. The user is granted access to a requested service only if
the information in the user profile allows it.
You can use the
aaa authorization
+ keyword to set parameters that restrict a user network access to
tacacs
privileged EXEC mode.
The
aaa authorization exec tacacs+ local
authorization parameters:
• Use TACACS+ for privileged EXEC access authorization if
authentication was performed by using TACACS+.
• Use the local database if authentication was not performed by using
TACACS+.
Authorization is bypassed for authenticated users who log in through CLI even
TIP
if authorization has been configured.
Beginning in privileged EXEC mode, follow these steps to specify TACACS+
authorization for privileged EXEC access and network services:
1. Enter global configuration mode.
configure terminal
2. Configure the wireless device for user TACACS+ authorization for all
network-related service requests.
aaa authorization network tacacs+
Rockwell Automation Publication 1783-UM006A-EN-P - May 2014
Administering the WAP Access
no aaa new-model
no aaa authentication
list-name} method1 [method2...] global
no login authentication {default
global configuration command with the
Chapter 6
global configuration
| list-
command sets these
217

Advertisement

Table of Contents
loading

This manual is also suitable for:

1783-wapak91783-wapek91783-wapck91783-wapzk9

Table of Contents