Zyxel IES-5106 [582/1156] Commands authorization screen

Zyxel IES-5106 [582/1156] Commands authorization screen
Chapter 15 Sys Screens
Management Switch Card User’s Guide
582
15.10.4 Commands Authorization Screen
In the Sys > AAA screen, click the Authorization section’s Advanced button to open this screen
where you can configure how the system checks whether a user is authorized to execute
commands of specific privilege levels.
Which commands a user can access can be controlled by command shell sets configured in the
TACACS + server. This allows you to set certain commands to only be authorized for a specific user.
For example, to allow only one user “A” to use the VoIP SIP commands, you can configure this
system so all the VoIP SIP commands require a specific privilege level and set the authorization
method for this privilege level to tacacs+. Then you set the command shell set configured in the
TACACS+ server to only give user “A” access to VoIP SIP commands.
See Section 39.6 on page 1091 for the command strings to have the TACACS+ server permit to in
order for a user to use various FTP actions.
Privilege This field is only configurable for Commands type of event. Select the threshold command
privilege level for which the system should send accounting information. The system will
send accounting information when commands at the level you specify and higher are
executed on the system.
Apply Click Apply to save the changes in this screen to the system’s volatile memory. The system
loses these changes if it is turned off or loses power, so use the Config Save link on the
navigation panel and then the Save button to save your changes to the non-volatile
memory when you are done configuring.
Cancel Click Cancel to begin configuring this screen afresh.
External Server Use this section to go to screens where you can configure your authentication server
settings (RADIUS, TACACS+ or both)
RADIUS Click Advanced to go to the screen where you can configure RADIUS server settings.
TACACS+ Click Advanced to go to the screen where you can configure TACACS+ server settings.
Table 315 Sys > AAA (continued)
LABEL DESCRIPTION

Содержание

Скачать