- exclude the current Acct-Session-Id from simultaneous-use checks - prevent TLS renegotiation from being rejected as a second login - keep Simultaneous-Use limited to fresh concurrent OpenVPN connections - preserve the existing RADIUS accounting session during TLS re-authentication