Thanks if they are seeing the rules break after three to five mins then it must be some other issue as i think the thing you show above only kicks in after 10 mins, right?
The scan is every 10 minutes, I assume it's every 10 minutes starting from when the miniupnpd daemon was started, not from when each individual port forwards have been established.
should they renew the nat-pmp mapping at the exact time it expires or a few seconds before? is there a best practice to stop the tcp session being torn down during renewal?
No idea, I'm no expert on the protocol itself, sorry.