I'm using time-based rules like this:
option weekdays 'Sun Mon Tue Wed Thu'
option src 'lan'
option name 'Desktop offtime: week night'
list src_ip '192.168.188.130'
option dest 'wan'
option target 'REJECT'
option start_time '22:15:00'
option stop_time '07:00:00'
and they seem to be basically working, but I've noticed that although new connections are blocked it seems that existing connections stay up. That's an issue as it doesn't kick my son off of Minecraft!
I found a setting (nf_conntrack_skip_filter) which I think might be related, but it seems to be deprecated or not recommended according to this page:
Does anyone know if that information is current, or if there is a newer/preferred way of doing this?