This might be a pain, but you can try it:
Create 1 pool with only the ip address you need for the first user
Create another pool with only the ip address you need for the second user
Create a role for the first user and attach the first VPN pool to that role
Create another role and attach the second VPN pool to that role
When the first user authenticates with VIA, the radius server should return the aruba-user-role attribute with the first role and assign the first pool
When the second user authenticates with VIA, the radius server should return the aruba-user-role attribute with the second role and assign the second pool.
Everyone else you do not return a role and they should get the default pool