Buy the 5yr warranty extension. Yes you can delay updates/make them manual. If I were you and weren't ready to give up the fortinet I'd double NAT it for a while, I think you'll find the benefit of using the complete ecosystem will convince you to give up the fortinet even if there are a few features that fortinet do better.
You can buy a firewall model that has the required controller built in requiring cloud connection or 2nd to that I'd setup a VM using the http://glennr.nl/ scripts as the controller. The scripts are reliable and capable.
I used to run 3rd party, like Sonicwall, firewalls with Unifi wifi for a few years but recent improvements to their approach has made me switch to the whole eco system now and I prefer it.