We configured 3 policies:
1 internal->wan1, web-ports only, low priority, limited bandwith, AV/IDS
2 Internal->otheroffice, vpn, low priority, limited bandwidth
3 internal pbx ip->otheroffice pbx ip, same vpn, high priority, max bandwidth
The pbx was connected directly with 100Mbit and the internal network with 10Mbit on the internal switch of the FTG60. We had max 0.5Mbit voice and 2-3Mbit other traffic.
Test have shown that the av/ids, configured only for general web traffic, influences the voip traffic heavily. With much less then the theoritical maximum of 10Mbit web traffic, you can get more then 5% packet loss in max 200ms delay. Average delay itself can get high as well.
Things get better if you connect the pbx on a separate ethernet, but even then you " see" the influence av/ids in the voice traffic.
Everything is fine with no internal network and no av/ids, but why should you use FortiGate at the end...