You could probably do this on the Funk Radius server, but you'll have to call Funk for help on that. ACS has a feature where it'll only authenticate users between certain times, so if Funk has a similar feature then that should be all you need. At any other times Funk will return a failure message and the user won't be able to get in.
Other than that, you can use time-based ACL's, but then this'll restrict all users from telnet'ing in during that time, since ACL's have no correlation to AAA usernames.
http://www.cisco.com/univercd/cc/td/doc/product/software/ios121/121cgcr/fun_r/frprt3/frd3003.htm#1027098