The outbound traffic will travel like this.
browser > webserver > through firewall > access local database and get data > back out through firewall > to users browser. (is that what you were referring to?)
The firewall is on the demarc of the local network taht allows traffic in + out
I want shared host to use one IP so I can lock down this traffic through my firewall, otherwise I have to specify "any" which I dont like, I'm currently looking to be able to specify a range of their shared hosts which I'm still uncomfortable with but i feel a little more comfortable with that, I would still much rather have a single IP but I think I would need to upgrade my service which I don't believe is an option...