Volker, you're talking nonsense, and you know that. netstat, TCPView, lsof, openports, fport and other tools like that show the status of ports on the local system from the INSIDE. Unless no services are listening on the external interface (which is desirable, but not always feasible) The output of these tools doesn't say anything at all about which ports are accessible from the OUTSIDE.
A local packet filter may or may not allow connections to port X. A SOHO router may or may not forward selected or all inbound connections to a particular host/port. None of the tools know the least about this.
Unfortunately Joe Average doesn't necessarily have a second computer he can plug into the router's external port. Or is familiar enough with commandline tools like nmap, scanline or PortQuery. Your advice also doesn't account for hosts that are directly on a dialup connection.
Although Joe Average shouldn't conduct a penetration test, there is nothing wrong at all with him running a port scan against his own border router to see, if all ports are closed (except for those he configured to be open).
cu
59cobalt