I have a PIX 515 that has a DMZ. I need to place a web server in the DMZ and have it access a MS SQL server inside our network. The server is 2008 R2. My plan is to connect a switch to the DMZ interface and then connect the web server to the switch. For access back to our SQL server I was thinking of using the second NIC on the web server and connecting that to a vlan on the switch and placing the SQL server's second NIC on the same vlan, both NICs using a completely different subnet than that of our internal network. Of course I would open the respective ports on the PIX needed for access. The switch that is connected to the DMZ would only have the web server and the sql server's second nic connected to it on their own vlan.
Is this a good plan from a security and operational standpoint? Do you see anything wrong with this plan or have any suggestions? What is a best practice?