Assign Privilege Levels with TACACS+ and RADIUS

AAA authorization limits the services available to a user.
When AAA authorization is enabled,  Devices uses information retrieved from the user profile, which is located either in the local user database or on the security server, to configure the user session.

The user is granted access to a requested service only if the information in the user profile allows it. You can use the aaa authorization command in global configuration mode with the tacacs+ keyword to set parameters that restrict a user network access to privileged EXEC mode.

The aaa authorization exec tacacs+ local command sets these authorization parameters:

• Use TACACS+ for privileged EXEC access authorization if authentication was performed by using TACACS+
• Use the local database if authentication was not performed by using TACACS+.

To determine the privilege level as a logged-in user, type the show privilege command.
To determine what commands are available at a particular privilege level for the version of Cisco IOS® software that you are using, type a ? at the command line when logged in at that privilege level.

Note: Instead of assigning privilege levels, you can do command authorization if the authentication server supports TACACS+. The RADIUS protocol does not support command authorization.
!
In this example,

snmp-server
commands are moved down from privilege level 15 (the default) to privilege level 7.
!
The ping command is moved up from privilege level 1 to privilege level 7.
!
When user seven is authenticated, that user is assigned privilege level 7 by the server and a show privilege command displays “Current privilege level is 7.” The user can ping and do snmp-server configuration in configuration mode. Other configuration commands are not available.
!
Configurations – Router :

aaa new-model
aaa authentication login default group tacacs+|radius local
aaa authorization exec default group tacacs+|radius local
username backup privilege 7 password 0 backup
tacacs-server host 171.68.118.101
tacacs-server key cisco
radius-server host 171.68.118.101
radius-server key cisco
privilege configure level 7 snmp-server host
privilege configure level 7 snmp-server enable
privilege configure level 7 snmp-server
privilege exec level 7 ping
privilege exec level 7 configure terminal
privilege exec level 7 configure
}
}
Cisco Secure UNIX TACACS+
Follow these steps to configure the server.
!
user = seven {
password = clear “seven”
service = shell {
set priv-lvl = 7
}
}
Cisco Secure NT RADIUS
Follow these steps to configure the server.
!
Enter the username and password.
In the Group Settings for IETF, Service-type (attribute 6) = Nas-Prompt
In the Cisco RADIUS area, check AV-Pair, and in the rectangular box underneath, enter shell:priv-lvl=7.

}
}

Cisco Secure UNIX RADIUS
user = seven{
radius=Cisco {
check_items= {
2=”seven”
}
reply_attributes= {
6=7
9,1=”shell:priv-lvl=7“
}
}
}
This is the user file for the username “seven.”
Note: The server must support Cisco av-pairs.
seven Password = passwdxyz
Service-Type = Shell-User
cisco-avpair =shell:priv-lvl=7