Do you mean in the DMZ of the firewall or really outside
I hope it's the former ...
I would look to place the SQL Server inside the firewall with a connection back from the web server in the DMZ. If you cannot do this, then in the DMZ it has to go.
If this is the case, backup locally and pull the files back using ftp/sftp. This should be easy on the firewall rules but don't forget to only allow connections from an IP address within the firewall. xcopy is an option but I would stay away from this if you are going through the firewall.
Hope this helps.