In summary, the DHCP relay agent receives DHCP messages and then
generates a new DHCP message to send out on another interface. The new
DHCP packet will be seen as local traffic (generated by the FortiGate).
That is why it is not blocked by firewall ...
Hello, UDP port 443 is Google's protocol QUIC
https://community.fortinet.com/t5/FortiGate/Technical-Note-Disabling-Blocking-QUIC-Protocol-to-force-Google/ta-p/191657