Protection or Simulation mode
During an initial acquaintance period or at any time, you can decide that FortiEDR acts as either of the following:
- Protection: FortiEDR enforces its active exfiltration prevention policy that blocks all connections that violate the relevant FortiEDR security policy rules.
- Simulation (Notification Only): FortiEDR only issues an alert (described below) for all connections that violate any rule in the FortiEDR security policy. In this mode, FortiEDR does not block exfiltration. FortiEDR comes out-of-the-box set to this mode.
If you have purchased a Content add-on license, policy rules and built-in exceptions are periodically automatically added or updated by Fortinet. When a new security policy is added, an indicator number displays on the SECURITY SETTINGS tab.
Use the Protection/Simulation slider at the far right of the window to enable the applicable mode, as shown below:
You can click the down arrow next to the Protection/Simulation slider to see an at-a-glance view of the system’s various security policies and their impact on the Collectors in the system.