Currently it is decided to swap FreeRADIUS and Cisco ISE. Cisco ISE works as authorization frontend and RADIUS Proxy (where external RADIUS Token Server is configured) , FreeRADIUS works as authentication backend. This configuration works well.