A lot of consumer connections these days are fully capable of saturating the typical business connection. Indeed, all it takes is three or four FiOS users watching Hulu or downloading shit to suck up an entire T3. By forcing full tunneling, you are trading the unlikely chance of detecting botnet communication from the client machine for the much more likely chance of an inadvertent DoS.
"But wait!," you say. "I block Hulu and other bandwidth intensive application, and I perform traffic shaping that prevents such bandwidth utilization."
Well, if you block traffic or throttle bandwidth, it's no longer transparent, and users have to start jumping through hoops.