Re: Link two PCs over two Fortigates
Then, for the client routing, you have to set the destination subnet as a part of routing address at the portal. You should check the routing table on the client machine once it's done.
If you use NAT for SSL VPN policy, the source IP for the packets go across the IPsec VPN use the tunnel interface IP. Make sure you configured the tunnel IP on both ends. Two /32 IPs work on both ends but generally recommended to pick ones in a /30 range, like 10.0.0.1/32 and 10.0.0.2/32. Then the other side of FGT knows where to route the returning packets.
Probably you took care of sets of policies on both ends. Since you're NATing, it's one way access. So you need only one policy on each FGT.
Then lastly make sure the phase2 selectors includes the access from the source tunnel IP, like 10.0.0.1/32, to the destination subnet.