I cant determine why you dont just terminate the tunnel on the PIXs DMZ interface but regardless, your solution should work fine. I used to do that all the time before the PIX supported IPsec. Just set a static and conduits in the PIX to the tunnel end point.