Port forwarding is not needed when using IPsec, as it does not create a virtual VPN interface. By default, from the Fortigate you should be able to reach the IP addresses specified within the “Remote subnets” field. So from the fortigate you should be able to reach the entire 10.100.10.8/30 network, and from the RUT950 you should be able to reach 172.22.44.0/22 subnet.
If that’s not the case, please share your IPsec configuration screenshots from the RUT950, as well as the Fortigate. Make sure to blur out the sensitive information!