I made a posting yesterday about my LOG being flooded by incoming connections from Google DNS ( 8.8.8.8 ) and thanks to mkx I could stop that by disabling the option Detect Internet under interfaces in the Mikrotik router.
viewtopic.php?f=2&t=141454
It looked like an attack, every second a connection came in on port 5768 and that is rather specific for Mikrotik routers. So this morning I started WireShark to see on what port Detect Internet was using to contact Google. Yes you guessed it, it was port 5768.
I think that it would be better to use random outgoing ports for Detect Internet.
I can't block the Detect Internet requests but the RAW rules will see the fall-out of Detect Internet.