I do see what you want to do. But just to clearify the radius serser’s responibility it to authenticate users saying good or no good. it’s the nas client that desides if one user should be able to connect one or many times simul… the radius server doesn’t know if the client to the nas client is still connected or not.

For that the nas client has to provide accounting but that is another story.
The sollution in radius only senarios is OTP…