i really don't know what to suggest. maybe try listening with tcpdump while you ping various sites, and while you use mozilla. see if that helps. here's a tcpdump session on my laptop (192.168.1.51) where i pinged 66.102.7.104 (
www.google.com) and then
www.google.com:
[root@lightstar:/var/log]$ tcpdump -i eth1 -n
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
13:20:19.787567 IP 192.168.1.50.138 > 192.168.1.255.138: NBT UDP PACKET(138)
13:20:42.690382 IP 192.168.1.51 > 66.102.7.104: icmp 64: echo request seq 1
13:20:42.750631 IP 66.102.7.104 > 192.168.1.51: icmp 64: echo reply seq 1
13:20:43.696912 IP 192.168.1.51 > 66.102.7.104: icmp 64: echo request seq 2
13:20:43.760114 IP 66.102.7.104 > 192.168.1.51: icmp 64: echo reply seq 2
13:20:44.706940 IP 192.168.1.51 > 66.102.7.104: icmp 64: echo request seq 3
13:20:44.733688 IP 66.102.7.104 > 192.168.1.51: icmp 64: echo reply seq 3
13:20:45.716911 IP 192.168.1.51 > 66.102.7.104: icmp 64: echo request seq 4
13:20:45.749187 IP 66.102.7.104 > 192.168.1.51: icmp 64: echo reply seq 4
13:20:46.726910 IP 192.168.1.51 > 66.102.7.104: icmp 64: echo request seq 5
13:20:46.776988 IP 66.102.7.104 > 192.168.1.51: icmp 64: echo reply seq 5
13:20:50.457736 IP 192.168.1.53.138 > 192.168.1.255.138: NBT UDP PACKET(138)
13:20:57.169471 IP 192.168.1.51.33152 > 4.2.2.4.53: 44560+ A?
www.google.com. (32)
13:20:57.205537 IP 4.2.2.4.53 > 192.168.1.51.33152: 44560 4/0/0 CNAME[|domain]
13:20:57.206139 IP 192.168.1.51 > 66.102.7.147: icmp 64: echo request seq 1
13:20:57.249972 IP 66.102.7.147 > 192.168.1.51: icmp 64: echo reply seq 1
13:20:57.250382 IP 192.168.1.51.33152 > 4.2.2.4.53: 55990+ PTR? 147.7.102.66.in-addr .arpa. (43)
13:20:57.290089 IP 4.2.2.4.53 > 192.168.1.51.33152: 55990 NXDomain 0/1/0 (103)
13:20:58.216913 IP 192.168.1.51 > 66.102.7.147: icmp 64: echo request seq 2
13:20:58.240937 IP 66.102.7.147 > 192.168.1.51: icmp 64: echo reply seq 2
13:20:58.241269 IP 192.168.1.51.33152 > 4.2.2.4.53: 17291+ PTR? 147.7.102.66.in-addr .arpa. (43)
13:20:58.261614 IP 4.2.2.4.53 > 192.168.1.51.33152: 17291 NXDomain 0/1/0 (103)
13:21:00.037382 IP 192.168.1.51.33152 > 4.2.2.4.53: 44519+ AAAA? ironmonkey.homelinu x.net. (42)
13:21:00.037933 IP 192.168.1.51.33153 > 4.2.2.4.53: 44668+ AAAA? imap.myrealbox.com. (36)
13:21:00.061329 IP 4.2.2.4.53 > 192.168.1.51.33152: 44519 0/1/0 (103)
13:21:00.061656 IP 192.168.1.51.33154 > 4.2.2.4.53: 56235+[|domain]
13:21:00.063718 IP 4.2.2.4.53 > 192.168.1.51.33153: 44668 0/1/0 (78)
13:21:00.063996 IP 192.168.1.51.33155 > 4.2.2.4.53: 54911+ AAAA? imap.myrealbox.com. dsl-verizon.net. (52)
13:21:00.090677 IP 4.2.2.4.53 > 192.168.1.51.33154: 56235 NXDomain 0/1/0 (128)
13:21:00.091009 IP 192.168.1.51.33156 > 4.2.2.4.53: 10319+ A? ironmonkey.homelinux.n et. (42)
13:21:00.093882 IP 4.2.2.4.53 > 192.168.1.51.33155: 54911 NXDomain 0/1/0 (122)
13:21:00.094074 IP 192.168.1.51.33157 > 4.2.2.4.53: 7241+ A? imap.myrealbox.com. (36 )
13:21:00.116328 IP 4.2.2.4.53 > 192.168.1.51.33157: 7241 1/0/0 A 192.108.102.201 (52 )
13:21:00.116679 IP 192.168.1.51.32920 > 192.108.102.201.143: S 1476868703:1476868703( 0) win 5840 <mss 1460,sackOK,timestamp 486607 0,nop,wscale 0>
13:21:00.126927 IP 4.2.2.4.53 > 192.168.1.51.33156: 10319 1/0/0 A[|domain]
13:21:00.127195 IP 192.168.1.51.32921 > 4.7.71.191.143: S 1490939251:1490939251(0) wi n 5840 <mss 1460,sackOK,timestamp 486609 0,nop,wscale 0>
13:21:00.167413 IP 192.108.102.201.143 > 192.168.1.51.32920: S 171214316:171214316(0) ack 1476868704 win 6144 <mss 1436,wscale 0,nop,sackOK,nop,nop>
13:21:00.167472 IP 192.168.1.51.32920 > 192.108.102.201.143: . ack 1 win 5840
the icmp packets are the pings. you can see that i resolve
www.google.com into an ip address by asking 4.2.2.4 (my provider's nameserver) on port 53. and anyway, you can tell that the conversation is ok. in your case, hopefully there will be some errors or something that will tell what's taking so long...