Perhaps the first rule doesn’t work because Tomcat keeps a forwarded request within the same webapp (ROOT.war in this case) and doesn’t delegate to another application with a completely different context path (/fi in your case). IMHO this would even make sense. You could try this by temporarily changing the forward to a redirect in the first rule.
Do you play Magic?
Get TopDecked MTG, the #1 Magic App, built by players, for players. Free to use, forever.