Try to change firewall dirty setting to check-new to see if it has same
behaviour.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Manage-policy-configuration-changes-behavior/ta-p/197421
If you have huge amont VIPS, like 2K-3K VIP, set interface will optimize
the performace, it will help traffice match the related interface, hope
it help.
When you tried to login by username and password, a csrf token returned,
you need post with this csrf token in http header. Use username/password
login has already fulfilled your request.