When traffic stopped working after disabling the monitor, do you see the IPSEC SA as Active or Inactive in the get sa?
Who is the initiator for the VPN: ISG or Fortigate? Please share the output for 'get log event type 536' to see if the VPN has gone down.
Thanks,
Pranita