Replacing Virtual Router with custom virtual appliance template
Don't know if this is still an open question, but here are my thoughts...
I don't believe that the Fortigate family has been integrated with CCP/ACS, but you could use "Shared/DirectAccess" networks to do most of this. The "Shared/DirectAccess" network, can be scoped to a single account for isolation. In this configuration, the VR will continue to do DHCP/DNS (the VR's DNS can forward to the Fortigate) and the Fortigate will act as the default gateway for the guest connected to the network.
You will lose the ability to configure LBs/Firewall Rules/StaticNats from within CCP, so this may not be an option for you.