I’ve run into this issue too — it’s tricky since IKEv2 tunnels don’t
always inherit DNS suffixes cleanly, especially with Intune-managed,
non-admin devices. One workaround is to push the suffix via Intune
custom configuration profiles using PowerShel...
Yes, it can be done. You can configure a FortiGate as a
router-on-a-stick by creating sub-interfaces on a single physical port,
each tied to a VLAN with its own IP. One of those VLANs can also provide
local access ports by bridging the sub-interface ...
Double-check that EMS log forwarding to FortiAnalyzer is enabled and
that both products are on compatible builds. You may also need to verify
the EMS connector settings under Device Manager. Fortinet docs list the
exact steps.