We strip Zips, (password protected or not), because I prefer to see the raw files themselves anyway. Generally this does not present a size issue for my company because most attachments are small(ish) Office docs.

We also block all executable content. Should executable content be required we will issue a login/passowrd combination to the FTP server in the DMZ and the user can place it there.