command authorization with radius ?

Dec 02, 2005 2 Replies

Hi all Recently i've tried to configure cisco 1751 with an exec command authorization on a radius server, namely freeradius. Unfortunately when i try to enter:



aaa authorization commands 15 default group rgroup none



the router is displaying:



%AAAA-4-SERVNOTACPLUS: The server-group "rgroup" is not a tacacs+ server group. Please define "rgroup" as a tacacs+ server group.



rgroup is defined as:



aaa group server radius rgroup server 10.1.1.1 auth-port 1812 acct-port 1813



Is it really not possible to use a radius server to do a command authorization ?



WM



Command authorization will work with tacacs+ only. We cannot have it with radius.

I do not believe the RADIUS protocol supports command authorization, only TACACS.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required