You need to set up proxy.
http://www.microsoft.com/technet/prodtechnol/winxppro/deploy/ed80211.mspx
Look for "Cross-Forest Authentication" in above link. And you get the Idea of what I mean. Though in above link its depicted with IAS server, but same is possible with ACS, as both can act as Radius server.
There is a known bug, CSCsi04187
PEAP MS-CHAP machine authentication will fail with machine not found if host/ format is sent from client. This only happens if the machine is autenticating to a domain forest that the ACS is not a member of.
Conditions:
The Machine authenticating to ACS is in a different domain forest then the ACS and the supplicant is using host/ as the machine name format. You also have to be using PEAP MS-CHAPv2.
Workaround:
If the supplicant has the option you can send the macine name in hos/ format.
Many supplicants do not have this option.
It is to be fixed for ACS 4.2 release.
Regards,
~JG