Mac authentication for few - overwhelming radius requests

I have enabled PAP and MAC authentication in the hotspot server profile to be authenticated via external radius and activated it on an interface…everything works fine when the user base is less …
now the user base has reached to 1000 and i have only 25 users for mac authentication and rest for hotspot based login…
i am getting every new session for mac authentication (though they are rejected by the radius, then the user gets the hotspot portal to login), worried that it might take down the radius server shortly …is there a way to apply a mac acl at hotspot input and allow only the specified mac’s for mac authentication and rest for hotspot authentication