cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Who Me Too'd this topic

AAA authorization commands

shahzadliaqat
Level 1
Level 1

Hi All

Probably i am going to ask a stupid question but i am really confused regarding the purpose of "aaa authorization commands x default local" command. I understand that if this command is configured, it authorizes each and every command of that level but in my experience, this command is not doing anything. The outcome is same whether it is configured or not.

Following is my aaa part config

username cisco privilege 15 secret cisco 

aaa new-model

aaa authentication login default local enable

aaa authorization exec default local if-authenticated

aaa authorization commands 15 default local if-authenticated

Now whether i keep the last command or remove it, username "cisco" is able to use every level 15 command so my question is, why i bother configuring this command?

 

Would really appreciate your quick reply

Regards

Who Me Too'd this topic