Re: SSL-VPN - Can we do this?
I highly doubt you could do that without slectively push routes in the split-tunnel, but you could enable explicit proxy and set the machines to use the fortigate as a proxy, why do you want split-tunnel and then route whitelisted URL thru the firewall? I don't see the logic in that request.
If your concern on web-filter for the end-users , deploy a full forticlient and control the end-point would be better regardless if he/she is on the vpn or not, IMHO. Here you can use the FC off-net and with all of the filteroptions with EMS endpoints.