CLI Guide

Security Commands 935
default
The default list of methods for authorization services
. The list
dfltCmdAuthList is the default list for command authorization and the
list dfltExecAuthList is the default list for Exec authorization.
list-name—
Character string used to name the list of authorization
methods. The list name can consist of any alphanumeric character up to
20 characters in length. Use quotes around the list name if embedded
blanks are contained in the list name.
method—The following authorization methods are supported:
local—Perform local authorization.
none—Do not perform authorization. All functions are authorized.
radius—Request authorization from the configured RADIUS servers.
tacacs—Request authorization from the configured TACACS+
servers.
Default Configuration
When authorization is enabled, the switch attempts to authorize the listed
function using the configured method.
Authorization is not enabled by default. Authorization supports Exec
authorization and network authorization for RADIUS. Only TACACS is
supported for command authorization. Setting a none or local method for
authorization authorizes Exec access for all functions.
The following default Authorization Methods List is present by default:
Command Mode
Global Configuration mode
User Guidelines
A maximum of five authorization method lists may be created for exec and
command types. The default methods may not be deleted.
Default List Name Description Authorization Method
dfltCmdAuthList Default Command List None
dfltExecAuthList Default Exec list None