Dear Richard,
In this case the client would always connect to example.com on port 7000 for example. Then based on which client cert is used to connect the client would be forwarded to a different IP:port. I'm not sure thats what you mean with Server Name Indication.
Yes, that's precisely what I mean by Server Name Indication support in stunnel.
I read your email once again and I discovered that I had misunderstood you. Stunnel only implements authentication based on client certificates and not authorization. I'm sorry for confusion.
Mike