One way to block access to your fortigate from the public IPs is to configure a local-in-policy.
configure address object
config firewall address
set subnet 126.96.36.199 255.255.255.0
If you have multiple subnets to block, You can configure more address-object and make an Address-object group
config firewall local-in-policy
set intf wan1
set srcaddr "public_IP_to_block" <--- Address-object or address-object-groupe
set dstaddr All <--- it can be all or you can define any address group ( like for block access to WAN1, configure an address-object for that WAN IP)
set action deny
set service All
set schedule "always"