B-27
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Appendix B      Configuring an External Server for Authorization and Authentication
  Configuring an External LDAP Server
Step 4 Verify the attribute map works as configured.
Using a PC as a remote user would, attempt connections using clientless SSL, the AnyConnect client, 
and the IPSec client. The clientless and AnyConnect connections should fail and the user should be 
informed that an unauthorized connection mechanism was the reason for the failed connection. The 
IPSec client should connect because IPSec is an allowed tunneling protocol according to attribute map.
Figure B-10 Login Denied Message for Clientless User
Figure B-11 Login Denied Message for AnyConnect Client User.