44
Ste
Command
Remarks
2. Enter user line view or
user line class view.
• To enter user line view:
line { first-number1
[ last-number1 ] | { aux | vty }
first-number2 [ last-number2 ] }
• To enter user line class view:
line class { aux | vty }
Use either command.
A setting in user line view is applied only to
the user line. A setting in user line class
view is applied to all user lines of the class.
A non-default setting in either view takes
precedence over a default setting in the
other view. A non-default setting in user
line view takes precedence over a
non-default setting in user line class view.
A setting in user line view takes effect
immediately and affects the online user. A
setting in user line class view does not
affect online users and takes effect only for
users who log in after the configuration is
completed.
3. Enable scheme
authentication.
authentication-mode scheme
By default, authentication is disabled for
AUX lines, and password authentication is
enabled for VTY lines.
In VTY line view, this command is
associated with the protocol inbound
command:
• If the setting of either command is not
the default in VTY line view, the setting
of the other command in VTY line view
takes effect.
• If the settings of both commands are the
defaults in VTY line view, the settings of
the commands in VTY line class view
take effect.
4. Enable command
authorization.
command authorization
By default, command authorization is
disabled, and the commands available for
a user only depend on the user role.
If the command authorization command is
configured in user line class view,
command authorization is enabled on all
user lines in the class, and you cannot
configure the undo command
authorization command in the view of a
user line in the class.
Configuration example
Network requirements
Configure the device in Figure 18 so a user can use Host A to log in to the device and execute only
commands that are authorized by the HWTACACS server or, when the HWTACACS server is not
available, the device itself.