bluetooth – Debian – Disallow Bluethooth Discovery

I run Debian and i do need Bluetooth to connect to my headset, but i do not want that devices can see my laptop nor being able to connect to it.

i have tried

rfkill unblock 0
bluetoothctl discoverable no
rfkill block 0

but this just kills Wifi, and if e re-enable wifi in my gnome-session, BT is discoverable

i also tried

hciconfig hci0 noscan

but this is A not persistent and does not work either.

a bit silly but i would like to handle it like i do tcpip connections with ufw:

deny incoming && allow outgoing

any ideas?