How to enable SSL Deep Packet Inspection on your FortiGate Firewall, and a couple of options for 'Trusting' the firewall from your clients. Either by distributing its certificate by Microsoft Group Policy, or creating a new SubCA certificate using Microsoft Certificate Services.
https://www.petenetlive.com/kb/article/0001729