In an authentication scenario the laptop does not directly "talk" to the Radius server. It is the switch or AP that "talks" to the Radius server (hence, why you setup those devices as "NAS" devices on the Radius server). But something is going on. Try looking at the windows client eventlog for authentications (if nothing shows up on the radius server logs that is). The switch should send a EAP-Id request when the session timeout happens (try verifying with a packetsniff). If it does not, well, then there is a problem, because your client would not know that the session has ended, and would still think it is connected. There is also a very old Windows 7 bug where the windows firewall would actually block all traffic for x amount of time, whenever a session timeout happened, as far as I remember.
... View more