In general that will work fine. This is also what I do quite often.
Another approach is to terminate the VLAN on the firewall to have more control who can communicate with the management-VLAN.
If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.