It's always a good practice to separate web servers, or any other service that you provide to the internet, into its own subnet. I'm not sure what the point is in having the PIX in the its own DMZ LAN, though. Simply put your web servers in the DMZ interface and your internal network in the inside interface. Configure a static NAT for the web servers, and NAT/PAT for the internal LAN.
-- Rubio