Detect Internet triggering flood of incoming connections

I made a posting yesterday about my LOG being flooded by incoming connections from Google DNS ( 8.8.8.8 ) and thanks to mkx I could stop that by disabling the option Detect Internet under interfaces in the Mikrotik router.

http://forum.mikrotik.com/t/killing-the-mikrotik-cloud/125034/1

It looked like an attack, every second a connection came in on port 5768 and that is rather specific for Mikrotik routers. So this morning I started WireShark to see on what port Detect Internet was using to contact Google. Yes you guessed it, it was port 5768.
Detectinternet.JPG
I think that it would be better to use random outgoing ports for Detect Internet.

I can’t block the Detect Internet requests but the RAW rules will see the fall-out of Detect Internet.