I'm facing this issue with the current implementation that we have.
We use the network 10.0.0.0/16 on our internal infra structure, if a client uses the forticlient on a guest wifi that uses the same subnet and connects to the forticlient the route will match to the internal guest wifi and not to the default route pointing to the fortigate.
My idea was to when the client connects to the ssl-vpn with the default route a route for 10.0.0.0/16 pointing to the tunnel should appear.
Do anyone had this same issue?
Also thought if is possible to do this on EMS and the "On Connect Script"
Our previous infra structure, cisco anyconnect that was possible.