1.5.3.1 Local Authorization

Information

Authorization controls authenticated users command execution and switch interaction privileges. Localauthorization uses role-based access control (RBAC) to provide role-based privilege levels plus optionaluser-defined local user groups with command execution rules. Authorization occurs only aftersuccessful authentication.

- Administrators have full command execution and switch interaction privilege.
- Operators are limited to the use of several nonsensitive show commands.
- Auditors are limited to a few auditing-related commands.

Optional per-command authorization is available through configuration of user-defined local usergroups with command authorization rules applied to respective group members.

Using local authorization on CX switches ensures faster authorization processes and eliminates dependency on external servers, enhancing reliability in scenarios where network connectivity to remote servers may be unavailable.

Solution

To enable local as primary authorization method -

switch(config)# aaa authorization commands {default | console | ssh | telnet} local

See Also

https://workbench.cisecurity.org/benchmarks/24202