А
The RADIUS-based method of command authorization requires less overhead on the AAA server and affords higher performance in environments that have many concurrent management sessions on the switches.
The examples in the following section describe the following:
Both Manager and “ViewOnly” levels of access are actually the same as far as the ArubaOS switch is concerned, with the only difference being which commands can be run.
The Manager-level of access still has command authorization as a RADIUS Vendor Specific Attribute (VSA), but there is no list of commands accompanying that role. When there is no list of commands, all commands can be run.
The ViewOnly-level of access has command authorization as a RADIUS Vendor Specific Attribute (VSA) and a command list with a regular expression indicating that only commands that begin with the word “show” may be run.
https://www.arubanetworks.com/techdocs/ClearPass/6.8/Aruba_DeployGd_HTML/Content/HP%20Switch%20Integration/Switch_mgmt_RADIUS.htm