After looking at the system requirements for Lync 2013 and glancing through some of the Lync server set-up guides (involving AD, IIS, PSTN analog gateways, dual/NIC teaming, QoS. etc), I would be more incline to deploy a more full-featured firewall appliance -- just because whatever Micrsoft may want you to install along/on top of Lync, that may need " protecting" .
Mind you, the Microsoft deployment guides assume/expect their edge server components are being installed.
The port list for Lync server is provided
here. I do not know enough about FortiWeb to know if it can block/allow/port redirect/forwarding to/from all these ports.
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C