Since all machines are acting the same, I would think the issue is with a common denominator to them, i.e. the server. I could see the switch being a possibility if it were a managed switch, but in this setup, it most likely isn't, and since you can ping sites, but not resolve them, it is not a switch issue. check the setting on the server for DNS, and group policies. Create a new user account on a workstation, does it have the same issues? does an admin account? are you able to get to the sites using the console on the server? have there been any software updates to the server? And you may think you are being accurate in your descriptions to the issue,but we don't know what setup you have, and everyone's environment is different, but we should not be learning that this effects all workstations in a domain environment in your third post, that should have been in the first. And before you change the topology of the network, think about the impact it will have on the other applications, and how they communicate. You have a domain setting, this isn't home networking 101, you can't go down to Best Buy and purchase a router off the shelf and install it without knowing what the consequences are to everything else in the network. Check the logs on the server, it should tell you when a workstation is attempting to go to an outside ip address, and when it fails, it should give a reason. Did you try disabling the firewall or antivirus on the server? In your setup it appears all internet activity goes through the server, so why not start there?