Since your device only support radius, you can use a Network Access Profile to match some set of conditions and apply some set of rules, for example, you can use the NAS-IP-Address attribute to match the ip address of this host from the Access-Request packet and tell that if this device comes to authenticate then authenticate to the local ACS DB, all other queries should be parsed normally. Take a look at the configuraiton guide of ACS particularly on the NAP section:
Table of ContentsIntroductionVersion HistoryPossible Future
UpdatesDocuments PurposeNAT Operation in ASA 8.3+ SectionsRule Types
Network Object NATTwice NAT / Manual NATRule Types used per SectionNAT
Types used with Twice NAT / Manual NAT and Network Obje...
Table of Contents Introduction:This document describes details on how
NAT-T works. Background: ESP encrypts all critical information,
encapsulating the entire inner TCP/UDP datagram within an ESP header.
ESP is an IP protocol in the same sense that TCP an...