I haven't set it up so I am not sure if it is possible. My guess is it has to do with the original "catch-all" VS clientssl profile. What do you have configured for the clientssl profile?
What you could do is instead of reselecting the virtual is a redirect. For example of they hit report.mysite.com you could redirect to "report-ap.mysite.com" which would start a new connection on that VS with the correct client sslprofile attached. If they request anon1.mysite.com you could redirect to anon-ap.mysite.com or something similar so you can reuse the same Access Profile for multiple hostnames.
Seth