> Isn't that the whole point of running a VPN connection?

Yes. What I'm saying is network operators are slowly forcing
everyone to run _everything_ over a VPN like service. That's
fine, but it makes network operators unable to act on the
traffic at the same level they can today.

How do they act on it today?

If you want a diff served VPN or anything done to something in it, you're
going to have to sign up for a service that can do that.. Or mark your vpn
streams on the outside accordingly... You can do that with IPSEC in TCP by
marking the wrapper if you wish..