Jose,
VSA 201 (Extreme-CLI-Authorization) set to Enable in Screenshot 2 forces EXOS to send each command to the RADIUS server for checking it against a profile to see if the user is authorized to issue that command or not. This feature is only available with a modified FreeRadius server.
Either delete this VSA or set it to 0 (Disable).
What you need to include in your user profile is the default Radius attribute
Service-Type set to
Administrative...
![9704cc6e28d84130b79249b195326a51_21415-7kumdy_inline.png 9704cc6e28d84130b79249b195326a51_21415-7kumdy_inline.png](/t5/image/serverpage/image-id/5475i774B3614CB93F1F1/image-size/large?v=v2&px=999)