what is this mean http://www.tiikoni.com/tis/view/?id=a57b49a
its in IP >> DNS
am i get dns hijacking or maybe some DNS attack?
Hi,
If you get flooded by dns attack then the RB’s cpu will max out at 100%
Also there will be a ton of entries inside the cache.
Disable allow remote requests to see if that entry goes away
how about maybe arp poisoning or arp spoofing
Something sent a packet to your router with source IP of 0.0.0.0 and your Mikrotik tried to resolve it for logging or something like that.
Or, something sent such a packet to one of the internal hosts of your LAN, and that host tried to do a reverse-dns lookup on 0.0.0.0 and it asked the Mikrotik, which cached the lookup failure.
This wouldn’t alarm me if I saw it in my router.