For the PIX to work propely, outgoing traffic and incoming traffic should pass through the same firewall. This is required since information about outgoing packets is cached and traffic is let in based on this information. The only thing that I can think of is to move your server back behind the old pix, to use a router in front of the PIX firewalls and have it direct traffic to one of the two firewalls depending on whther it is intended for the desktop Server or not. You should also keep the two segments isolated except for the connection through the router.