The permit chosen to tie a group of NetIDs to an IP pool must be configured to allow permit queries by the RADIUS server. The RADIUS server, in the process of handling authentication requests, identifies itself to permit with a Kerberos principal. It is that principal that will be granted query access to your permit.
- Connect to https://paw1.cit.cornell.edu/cgi-bin/permit.cgi.
- When prompted, in the NetID box, enter your NetID. In the Password box, enter your NetID password, and then click Login.

- In the Permit Access List, in the Admin column, select the name of the permit, for example permit_name. Then click Update ACL List, and click Execute.

- In the Look Up column, in the text box next to the Add NetID button, enter radius-proxy.agate1, and then click Add NetID.

- At the bottom of the screen, click Return to Permit Access List.
- In the Permit Access List, in the Admin column, select the name of the permit, for example permit_name. Then click Update Permit Characteristics, and click Execute.

- On the Permit Characteristics form, in the Visible column, confirm that the current status is Yes. If necessary, use the Change Status list to change the status to Yes, and then click Make Changes.

- Close the browser window when you're finished updating the permit.