When clients connect using the L2TP-over-IPsec VPN, the FortiGate unit checks their credentials against the user group you specify for L2TP authentication. You need to create a firewall user group to use for this purpose. Creating a user group – web-based manager. Go to User & Device > User Groups, select Create New, and enter the following:

Cookbook | FortiGate / FortiOS 6.0.0 | Fortinet IPsec VPN with FortiClient. In this example, you allow remote users to access the corporate network using an IPsec VPN that they connect to using FortiClient. The remote user Internet traffic is also routed through the FortiGate (split tunneling will not be enabled). FortiClient VPN - Apps on Google Play Jun 19, 2020 Forticlient - Next Generation Endpoint Protection

Overview Bài viết hướng dẫn cấu hình tính năng IPSec VPN Client to site trên thiết bị Fortigate để các thiết bị có thể truy cập và hệ thống mạng nội bộ từ xa một cách an toàn Hướng dẫn cấu hình Đăng nhập vào thiết bị Fortigate bằng tài khoản Admin User & Device -> User Definit

When a dialup IPsec VPN client is connected to a VPN, it is effectively becoming a member of the local network located behind FortiGate. For this reason, all of its traffic (even Internet traffic) has to be forwarded inside the IPsec tunnel to FortiGate, inspected by the respective firewall policies, forwarded to Internet and then back to the FortiGate vs Meraki - Networking - Spiceworks Apr 20, 2020 Fortinet Knowledge Base - View Document

Yes it is possible to use a Fortigate as a VPN client, took me a long while to figure out there i'm relatively new to the Fortigate world but helped my learning curve greatly! I have it working with NordVPN. On the website of Nordvpn there is a description on how to setup an L2TP connection initiated from you WAN interface.

IPsec VPN with the native Mac OS client – Fortinet Cookbook