Ask about DNS

what is this mean http://www.tiikoni.com/tis/view/?id=a57b49a
its in IP >> DNS
am i get dns hijacking or maybe some DNS attack?

Hi,

If you get flooded by dns attack then the RB’s cpu will max out at 100%

Also there will be a ton of entries inside the cache.

Disable allow remote requests to see if that entry goes away

how about maybe arp poisoning or arp spoofing

Something sent a packet to your router with source IP of 0.0.0.0 and your Mikrotik tried to resolve it for logging or something like that.
Or, something sent such a packet to one of the internal hosts of your LAN, and that host tried to do a reverse-dns lookup on 0.0.0.0 and it asked the Mikrotik, which cached the lookup failure.

This wouldn’t alarm me if I saw it in my router.