User Manager and Hotspot, only for the braves

Since too many hours now I am trying to get the hotspot working with user manager… but radius server is, you guess? not responding.
I read all the topics and tried all the suggestions with no luck.
Here is my config:
172.17.2.3 172.17.2.4 and 172.17.2.5 are APs connected in ethernet on the same switch
User Man is on 172.17.2.4
One of our Internet gateway and Hotspot is on 192.168.253.254, which has a PTP address (192.168.253.254/30) on a wds interface for a wireless link with 172.17.2.3 (whose wds interface address is of course 192.168.253.253)
All those routers are RB532a with ROS 2.9.42

Connected to the ethernet port of 192.168.253.254 router, there is the broadband router.

Hotspot is set on 192.168.253.254 wds interface, radius is enabled for the hotspot and incoming is set to yes, as from the wiki and previous posts
From 172.17.2.4 I ping 192.168.253.254 and vice versa (I included an icmp rule in the hotspot walled garden)

The problem is:
192.168.253.254 sends the auth request to 172.17.2.4 and from what I can see from the logs, the user man authorises the user

test1 172.17.2.70 192.168.253.254 Apr/28/2007 17:57:41 authorization success

But the answer never arrives to the hotspot…
I tried to increase the timeout up to 3 seconds, no luck
I tried to include the relevant ip and ports of both user man server and hotspot, nothing happens.
Do you have any idea of what should I try?

Thank you

Well, I got it, the problem was I forgot to set up Ip bindings to let 172.17.2.4 bypass the hotspot.