You can create an expression to be used during the role mapping. We are using this one, associated with a stop rule in the begin of the role mapping. Explanation: user of LDAP group block_0030_0800, and time between 00:30 to 08:00
time = (00:30 TO 08:00)
If you what at 11PM the VPN Session be disconnected, you must Enable dynamic policy evaluation at realm level.
I hope it helps.