In this tutorial i have explained what happens when the Radius server is not reachable in the CISCO ESA.
I have shown the Radius config for Two Factor Auth in brief.
I have shown the logs of the ESA when this happens.
So, if your 2FA is not working as expected and you lose access to your appliance, then you need to get the console access to your ESA and disable 2FA from there and then work on fixing the problem.
Not necessarily disable MFA but you can do whatever you want from there without being asked to identify yourself the second time.