putting the phone router in the DMZ wouldnt work, if it absolutely needs to physically have a public IP, then it has to be outside of the firewall on a spare IP address. So this is effectively also plugged into the WAN-ISP Router network.
This obviously means your phone router is unprotected by the fortinet. But this is what would happen if they insist on a public IP.
there is one other way to do it, but requires you to lose a chunk of your provided ISP IP range, and you would need to work with the ISP to reconfigure their router to narrow the subnet and add routes to your fortinet (to essentially put a subnet of your current range on another internal network. this would also require a spare interface port as well.
UK Based Technical Consultant
FCSE v2.5
FCSE v2.8
FCNSP v3
Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.