Norman Zhang wrote:
> Thanks. I edited users with the following entries
> 
> DEFAULT       Auth-Type = System
>       Fall-Through = 1,
>       cisco-avpair = "shell:priv-lvl=1",
>       Service-Type = Administrative-User
> 
> DEFAULT Group == user-ro
>       cisco-avpair := "shell:priv-lvl=7"
> 
> DEFAULT Group == user-rw
>       cisco-avpair := "shell:priv-lvl=15"
> 
> but all users still get privilege level 15 access. Something wrong with 
> my config?

Found it. Service-Type should = NAS-Prompt-User.

Norman

- 
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html

Reply via email to