Re: Double routers with FortiGate on the LAN.
The Interface your Fritz!Box is connectrd to is acting as you rWAN for internet then right?
I have one site here that has a Fritz!Box as one WAN too. So Fritz!Box is connected to one of the WAN ports (but you could use any other port too) and I put it into sd-wan as I need some loadblancing to happen.
Then there is just policies to allow traffic to flow that I need to be able to reach the Fritz!Box (like I need to access to Froitz fro HQ via S2S IPsec on the FGT) and it is fine.
Just for inside services (like I had to to for ipsec) you then might have to do some port forwarding on the Frtz...
-- "It is a mistake to think you can solve any major problems just with potatoes."
- Douglas Adams