I think you'll be creating a lot of pain for yourself. These usually sit behind home routers, so you'll probably need to setup port forwards on those ISP devices, and then most ISP connections use dynamic IP addresses - so you'll have to cope with that on your Fortigate.
A much simpler solution would be to also get a little MX67 and run it in VPN concentrator mode, and sit it behind your Foritgate. The Z3s can use AutoVPN to automatically build a VPN to that device. On your Foritgate you would then just add static routes via the MX67 for the remote sites.
https://documentation.meraki.com/MX/Deployment_Guides/VPN_Concentrator_Deployment_Guide