Re: Host isolation?
Native vlan is the vlan that an untagged frame gets assigned by default.
Allowed is (usually) other vlan IDs that are allowed on that port.
If you're working with FortiGate managed switches using 3.6.x firmware you can't force tagged or untagged frames on a port from the GUI or even the FortiGate's CLI. You can ssh to the switch, though, and set it for a specific port, by setting discard-mode to all-tagged or all-untagged.
If you're running a FortiGate on 6.0.x and a managed FortiSwitch on 6.0.x you can set the same thing, just from the config switch-controller managed-switch section.
BTW, I'd recommend you don't use and don't delete vlan1. IIRC, it may be used by the FortiSwitch.