Can you post your config to further assist.
Please make sure you are allowing http, https, dns, ntp, and port 8888 at a minimum from your internal to wan.
Also, I would recommend going to system, fortiguard. Make sure under fortiguard filtering port is set to 8888.
If you have any other interfaces, I would make sure they also have http, https, dns, and ntp allowed to wan.
In addition, I would recommend setting your FGT dns to the closest server to you. I have had the best luck if an internal dns is used and then place forwarders in active directory dns to whatever dns you want. Example, if you use Comcast, use their dns servers in FGT. Also, place any other network dns to the closest dns server. Example, If you have a separate wifi interface, specify that same dns server. Example, Comcast is 22.214.171.124.
Waiting to receive your config if you are still having problems.