Local overrides of remote user mappings

Prev Next

When remote users are authenticated by a remote server, they are logged in to the appliance as a local user and are granted the same access privileges as that user. For any remote authentication method, the mapping of a remote user to a local user is configured in a method-specific attribute string that is returned by the remote server after a user is authenticated.

You can use the aaa authorization rules rule command to configure rules in the local configuration to override this mapping when specified conditions are met. This is described in the following topics:

If the user is authenticated by the remote server but the remote server does not return the attribute string, the remote user is logged in as the default local user. This is specified by the aaa authorization map default-user CLI command, as described in the following topic: