Thanks for posting your question in the Microsoft Q&A forum.
Since FortiGate Firewall is already managing traffic, I believe you don’t necessarily need an Azure firewall policy on the Application Gateway.
However, consider the following points:
- Network Security Groups (NSGs): Ensure that NSGs are configured correctly to allow traffic between VNET A and VNET B.
- Application Security: If your web applications require additional protection, consider enabling WAF on the Application Gateway.
- Routing: Set up proper routing so that traffic flows through FortiGate (via UDRs) when reaching the Application Gateway.
** Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful **