Посмотрел архивные конфиги радиуса для подобных клиентов. Как-то так, два варианта:
user1 NAS-IP-Address == "10.88.0.161", Service-Type == Login-User, Auth-Type := Accept
Auth-Type := Accept,
Service-Type = Login-User,
Cisco-AVPair = "shell:autocmd=telnet 1.2.3.4 23 /vrf External",
Fall-Through = No
user2 Service-Type == Login-User
Service-Type = Login-User,
Login-Service = Telnet,
Login-IP-Host = 1.2.3.5,
Login-TCP-Port = 20029,
Fall-Through = No