We have a hardware apliance that does RAS for us, it points to our BM3.8
Radius box for authentication. It can have at most 3 authetication
radius server addresses. If it gets a radius response from one server,
(whether approved or not) it stops looking. BM3.8 makes good fail over
that way (if one server is not responding to radius request, the Ras box
will go to the next server) but it does not help me when the user I need
to authenticate is in another tree.

Is there a way to have a radius serve support multiple trees...maybe
with running on the servers where those other trees reside or something?

So far the only answer I have is to define users in both trees...a fact
that gets me odd looks at audit time when I have many more users than I
should.....