You should always use a WAF for web-based applications. Preferably one
cloud hosted like CloudFlare, etc to also offer DDOS prevention. Are you
decrypting on the FortiGate for the inbound traffic? If not the firewall
is essentially blind to all traff...