To achieve this, we can set traffic policy and apply it in the inbound direction of Gi0/0/0(internal network) to prevent packet matching the rule of ACL.
Configuration:
time-range work 09:00 to 18:00 working-day
time-range work 09:00 to 13:00 Sat
#
diffserv domain default
#
acl number 2000
rule 5 permit time-range work
rule 10 deny
interface GigabitEthernet0/0/1
traffic-filter outbound acl 2000