This thread was automatically locked due to age.
Very difficult to understand your question, Mina. Hopefully you get a moment to update the wording but are you saying you use a FortiGate as your Gateway with a Sophos XGS unit behind the FortiGate for Securing the network, providing DHCP? But you would like to VPN into the Fortigate and have access to the LAN zone and XGS for management?
You may want to hit up Fortinet for that configuration, or better yet, connect your XGS directly to Internet and use Sophos Connect (SSL VPN or IPSec), or consider options with Sophos ZTNA.
While there is more than one way to make this work, for remote access users you will want to ensure that the networks they want to reach are in the VPN policy they were assigned, that the firewall rules permit the traffic, and that the XGS is configured to permit access from that source.