Is someone doing a man in the middle attack on me? I just looked in my firewall connections and I see a lot of traffic going to 192.168.1.44, I think someones doing a MITM attack one me, what do you think?? btw 192.168.1.x is upstream of me, it is the AP that is serving my network above my client. Also I have set Filter rules to block connections to this ip and it doesnt stop the connections at all. Ive also noticed all my dns requests on port 53 go to this host.

Oh it gets better, wtf is 192.168.1.44 doing as a preferred source?!?!!?

All my dns requests are also going to that.

Oh but w8, it gets better, ITS A MIKROTIK BOX!?!?!?
Starting Nmap 5.35DC1 ( http://nmap.org ) at 2010-12-17 16:30 Pacific Standard Time
NSE: Loaded 49 scripts for scanning.
Initiating Ping Scan at 16:30
Scanning 192.168.1.44 [4 ports]
Completed Ping Scan at 16:30, 0.33s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 16:30
Completed Parallel DNS resolution of 1 host. at 16:30, 0.05s elapsed
Initiating SYN Stealth Scan at 16:30
Scanning 192.168.1.44 [1000 ports]
Discovered open port 53/tcp on 192.168.1.44
Discovered open port 22/tcp on 192.168.1.44
Discovered open port 23/tcp on 192.168.1.44
Discovered open port 1080/tcp on 192.168.1.44
Discovered open port 8291/tcp on 192.168.1.44
Discovered open port 2000/tcp on 192.168.1.44
Completed SYN Stealth Scan at 16:30, 4.63s elapsed (1000 total ports)
Initiating Service scan at 16:30
While I was writing this my client that is connected to it went down for some mysterious reason.