Okay. If the VIP is on an F5 (and not CPPM) just remove all of the servers and then add the F5 ip address. That should be it... Is there something keeping you from doing that? Existing clients should still authenticate to the specific radius server that they authenticated to before. If you are skeptical, just do it in two steps, after hours.