This is a fairly common scenario, and is not too complicated. Essentially, you need a site-to-site VPN to connect your FortiGate to the other resource (assuming the other resource is being another FortiGate for ease of explanation). Then you need to user facing SSL-VPN portal for accessing the networks behind the FortiGate.
In other words:
User <--- SSL-VPN ---> FortiGate <--- IPsec VPN ---> FortiGate <--> internal resources.
Check out this document for more info how it is configured:
FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.
1 Person is following this question.