Implement velia-firewall

Change-Id: I228f15fca7ed784bf1043e4074cf8e76fcd6a842
diff --git a/package/cla-sysrepo/czechlight-install-yang.sh b/package/cla-sysrepo/czechlight-install-yang.sh
index f0d26fa..b4484d6 100755
--- a/package/cla-sysrepo/czechlight-install-yang.sh
+++ b/package/cla-sysrepo/czechlight-install-yang.sh
@@ -117,5 +117,11 @@
     sysrepoctl --change czechlight-system --permissions 0664 --apply
 fi
 
+if [[ ! -f ${REPO}/czechlight-firewall@2021-01-25.yang ]]; then
+    sysrepoctl --search-dirs /usr/share/velia/yang --install /usr/share/velia/yang/czechlight-firewall@2021-01-25.yang
+    sysrepoctl --change czechlight-firewall --permissions 0600 --apply
+    sysrepoctl --change ietf-access-control-list --enable-feature eth --enable-feature match-on-eth --enable-feature match-on-ipv4 --enable-feature ipv4 --enable-feature match-on-ipv6 --enable-feature ipv6 --enable-feature mixed-eth-ipv4-ipv6
+fi
+
 # If not do not copy here from startup -> running, running might be stale.
 sysrepocfg -C startup