To disable AAA configuration command authorization in the EXEC mode, use the no form of the aaa authorization config-commands global configuration command. Use the standardform of this command to reestablish the default created when the aaa authorization commandslevelmethod1command was issued.
aaa authorization config-commands
no aaa authorization config-commands
This command has no arguments or keywords.
After the aaa authorizationcommandslevelmethod has been issued, this command is enabled by defaultmeaning that all configuration commands in the EXEC mode will be authorized.
Global configuration
Release | Modification | 11.2 | This command was introduced. |
---|
If aaa authorizationcommandslevelmethodis enabled, all commands, including configuration commands, are authorized by AAA using the method specified. Because there are configuration commands that are identical to some EXEC-level commands, there can be some confusion in the authorization process. Using no aaa authorization config-commands stops the network access server from attempting configuration command authorization.
After the no form of this command has been entered, AAA authorization of configuration commands is completely disabled. Care should be taken before entering the no form of this command because it potentially reduces the amount of administrative control on configuration commands.
Use the aaa authorization config-commands command if, after using the no form of this command, you need to reestablish the default set by the aaa authorizationcommandslevelmethod command.
The following example specifies that TACACS+ authorization is run for level 15 commands and that AAA authorization of configuration commands is disabled:
aaa new-model aaa authorization command 15 tacacs+ none no aaa authorization config-commands
Command | Description |
---|---|
aaa authorization | Sets parameters that restrict network access to a user. |
Printed for apswan@ctr.ap.nic.in on Wed Mar 5 22:32:57 PST 2003
All material in this document copyright 2000 Cisco Systems, Inc. All rights reserved. No material may be reproduced or distributed without written permission of Cisco Systems, Inc.