I would like to add one note of caution.......
Deploying VENs in visibility mode is not always 100% safe, and can indeed effect traffic in specific scenarios. The scenario that caught us off-guard, with the belief that visibility mode can't effect anything, was with Linux servers running Docker. Having the VEN in visibility mode without configuring Containers Policy on a server using Docker will still cause Illumio to take over IPTABLES. When it does this it disables IP Forwarding, which basically breaks the Docker setup.
Unless you are certain you are not using containers in your environment it may be safest to install the VEN in idle mode, at least for Linux. Then check the Compatibility Report, configure Container Policy where needed, then place the server(s) into visibility mode. If you are dealing with a larger rollout, that total process is easiest done using the workloader tool.
On a side note..... We found it easiest to create a new label called F-CONTAINER, add that label to the Containers Policy, then add the label to servers that need it.