It's just silly to force the entire org to be on that model, especially since it includes Insight which is not org centric. You can already split IP range from VPN, not sure why you have to force an org upgrade to split a single networks traffic from VPN when detecting by app rather than IP range.